profiling-stack
Chart · Stacks · standard · v0.0.2
Hardened continuous profiling stack: Grafana Pyroscope (profile store and query) + Grafana with the Pyroscope datasource provisioned.
Version
The latest line lives at the base page; older lines have their own page so you can pin and verify exactly that version.
Deployed image digest
sha256:9fd3dc0ff132dd7e0ca040ecfbd178f42b8571d46b3c56ffec041a5e518696daChart OCI version
oci://ghcr.io/quenchworks/charts/profiling-stack:0.0.2The chart pins its image by this signed digest, so you never track it yourself. Signatures, SBOM, and provenance attach to the same digest.
Install the chart
Deploy to Kubernetes with hardened defaults. The chart pins its image by signed digest, so you never track it yourself.
Install (latest)
helm install my-profiling-stack oci://ghcr.io/quenchworks/charts/profiling-stack --version 0.0.2Deploys image (digest-pinned)
ghcr.io/quenchworks/images/pyroscope@sha256:9fd3dc0ff132dd7e0ca040ecfbd178f42b8571d46b3c56ffec041a5e518696da
ghcr.io/quenchworks/images/grafana@sha256:4b7e7a1342831602a31232c1dce40d8ea6a14bb44d6acb3aa095c029e1520d55Charts used:
- Chart version
- 0.0.2
- App version
- 1.0.0
- Chart license
- Apache-2.0
- App license
- Unknown
- Signed
- cosign (keyless)
- Values schema
- yes
- Last published
- 2026-10-05
Verify the chart
cosign verify ghcr.io/quenchworks/charts/profiling-stack:0.0.2 \
--certificate-identity-regexp 'https://github.com/quenchworks/.+' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comTransparency
The chart publishes its attestations on GitHub and the image it deploys carries its own on the same digest, publicly verifiable with the commands above. Both log to the Sigstore transparency log (Rekor), which cosign verify checks for you.